CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,607)
page 37 of 2,331| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-6033 | Hig | 0.57 | 8.7 | 0.01 | Dec 1, 2023 | Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser. | ||
| CVE-2023-26222 | Hig | 0.57 | 8.7 | 0.00 | Nov 14, 2023 | The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system.… | ||
| CVE-2023-46238 | Hig | 0.57 | 8.7 | 0.00 | Oct 26, 2023 | ZITADEL is an identity infrastructure management system. ZITADEL users can upload their own avatar image using various image types including SVG. SVG can include scripts, such as javascript, which can be executed during rendering. Due to a missing security header, an attacker… | ||
| CVE-2023-41895 | Hig | 0.57 | 8.8 | 0.01 | Oct 19, 2023 | Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that specifies the `redirect_uri` and `client_id` parameters. Although the `redirect_uri` validation typically… | ||
| CVE-2023-38219 | Hig | 0.57 | 8.7 | 0.01 | Oct 13, 2023 | Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into… | ||
| CVE-2023-0829 | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2023 | Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription. | ||
| CVE-2023-39370 | Hig | 0.57 | 8.8 | 0.00 | Sep 3, 2023 | StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79) | ||
| CVE-2023-39369 | Hig | 0.57 | 8.8 | 0.00 | Sep 3, 2023 | StarTrinity Softswitch version 2023-02-16 - Multiple Reflected XSS (CWE-79) | ||
| CVE-2023-37221 | Hig | 0.57 | 8.8 | 0.00 | Sep 3, 2023 | 7Twenty BOT - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). | ||
| CVE-2023-4296 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2023 | If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the target device. | ||
| CVE-2023-33159 | Hig | 0.57 | 8.8 | 0.01 | Jul 11, 2023 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2023-29347 | Hig | 0.57 | 8.7 | 0.02 | Jul 11, 2023 | Windows Admin Center Spoofing Vulnerability | ||
| CVE-2023-2072 | Hig | 0.57 | 8.8 | 0.01 | Jul 11, 2023 | The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on… | ||
| CVE-2023-36390 | Hig | 0.57 | 8.8 | 0.00 | Jul 11, 2023 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),… | ||
| CVE-2023-36389 | Hig | 0.57 | 8.8 | 0.00 | Jul 11, 2023 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),… | ||
| CVE-2023-36386 | Hig | 0.57 | 8.8 | 0.00 | Jul 11, 2023 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),… | ||
| CVE-2021-42083 | Hig | 0.57 | 8.7 | 0.01 | Jul 10, 2023 | An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab * add a webhook with the URL/service token value ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) * … | ||
| CVE-2023-35971 | Hig | 0.57 | 8.8 | 0.01 | Jul 5, 2023 | A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in… | ||
| CVE-2023-36345 | Hig | 0.57 | 8.8 | 0.01 | Jun 23, 2023 | A Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges. | ||
| CVE-2023-34088 | Hig | 0.57 | 8.7 | 0.00 | May 31, 2023 | Collabora Online is a collaborative online office suite. A stored cross-site scripting (XSS) vulnerability was found in Collabora Online prior to versions 22.05.13, 21.11.9.1, and 6.4.27. An attacker could create a document with an XSS payload as a document name. Later, if an… |
- risk 0.57cvss 8.7epss 0.01
Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.
- risk 0.57cvss 8.7epss 0.00
The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system.…
- risk 0.57cvss 8.7epss 0.00
ZITADEL is an identity infrastructure management system. ZITADEL users can upload their own avatar image using various image types including SVG. SVG can include scripts, such as javascript, which can be executed during rendering. Due to a missing security header, an attacker…
- risk 0.57cvss 8.8epss 0.01
Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that specifies the `redirect_uri` and `client_id` parameters. Although the `redirect_uri` validation typically…
- risk 0.57cvss 8.7epss 0.01
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into…
- risk 0.57cvss 8.8epss 0.01
Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
- risk 0.57cvss 8.8epss 0.00
StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79)
- risk 0.57cvss 8.8epss 0.00
StarTrinity Softswitch version 2023-02-16 - Multiple Reflected XSS (CWE-79)
- risk 0.57cvss 8.8epss 0.00
7Twenty BOT - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
- risk 0.57cvss 8.8epss 0.01
If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the target device.
- risk 0.57cvss 8.8epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.57cvss 8.7epss 0.02
Windows Admin Center Spoofing Vulnerability
- risk 0.57cvss 8.8epss 0.01
The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on…
- risk 0.57cvss 8.8epss 0.00
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…
- risk 0.57cvss 8.8epss 0.00
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…
- risk 0.57cvss 8.8epss 0.00
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…
- risk 0.57cvss 8.7epss 0.01
An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab * add a webhook with the URL/service token value ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) * …
- risk 0.57cvss 8.8epss 0.01
A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in…
- risk 0.57cvss 8.8epss 0.01
A Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges.
- risk 0.57cvss 8.7epss 0.00
Collabora Online is a collaborative online office suite. A stored cross-site scripting (XSS) vulnerability was found in Collabora Online prior to versions 22.05.13, 21.11.9.1, and 6.4.27. An attacker could create a document with an XSS payload as a document name. Later, if an…